Random Password shows in clear text in AD

fouriefb
Regular Contributor
Regular Contributor

Good day all,

Just wanting to find out if anyone has a solution to mask a random password created in AD from LDAPS via CreateAccountJSON.

Problem is if you do not generate a password, then account gets created disabled in AD and customer would need to enable account.

I understand this is a flaw in ldaps password create but looking to see if anyone has a solution or workaround

Thanks

3 REPLIES 3

timchengappa
Saviynt Employee
Saviynt Employee

Hello @fouriefb 

May I ask, where you are seeing the password in plaintext? Is it in Saviynt logs or are you referring to actual metadata in Active Directory itself?

Hi @timchengappa 

We are seeing this in AD metadata after account has been provisioned.

 

timchengappa
Saviynt Employee
Saviynt Employee

Hi @florasargsyan 

Thanks for the clarification.To my knowledge, the Saviynt application will not have control over this...
Perhaps check on the AD team if making passwords is an option.